ALMA Communicator – DNS Tunneling Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
It is delivered by a specially crafted Excel document (called “Clayslide” by OilRig) that contains malicious macros. When opened, this file asks users to enable extra content before executing the macros and dropping ALMA on the system. It is important to note that ALMA has no internal configuration, instead relying on the Clayslide file for this.
As it communicates using DNS requests, ALMA can only handle very limited volumes of data (download 10 bytes and upload 4 bytes per request). As such, any sizeable amount of data will generate a large number of DNS request, potentially alerting a user to an infection.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
Last edited: 17 February 2020 11:25 am